RRecords Labs Help Center

Knowledge scope and audiences

Every agent has a knowledge scope: the part of your organization's knowledge it is allowed to read. Scope never widens anyone's access. A person asking the agent still sees only what their own permissions allow, and a customer on a public channel sees only what you have marked for that audience.

The three scope modes

On the agent's Knowledge step you choose one of:

  • Everything: the whole brain. Each person still sees only what they are permitted to.

  • Selected knowledge: only the sources, documents, tags and teams you choose.

  • No knowledge: persona only. The agent answers without reading any sources.

New agents start on Everything.

Rules in Selected knowledge

Selected knowledge is a list of rules. Each rule has a kind, a target, and a mode (include or exclude).

The kinds you can add are:

  • Connector: everything a connected system brings in.

  • Source: one source, such as a website crawl or a synced folder.

  • Item: one document or note, pinned exactly.

  • Tag and Category: labels applied to items.

  • Team: knowledge owned by a team.

  • Audience: a whole visibility tier.

An agent set up before the current rules builder may also show an Auto-include rule named "Imported access rule". It carries the older access settings over and keeps matching new content. You can switch it between Include and Exclude or remove it, but you can't add a new one.

Rules fall into two groups in the Included knowledge list:

  • Living rules auto-update as new content matches them. A connector, source, tag, category, team, audience or auto-include rule is living.

  • Pinned items are exactly the items you picked. Nothing is added on its own.

To build the list:

  1. Under Add knowledge, use the All, Sources, Items, Labels and Teams tabs and search.

  2. Click Add to include something or Exclude to keep it out. On a connector you can Include all.

  3. Flip any rule between Include and Exclude later, remove it with the X, or Clear all.

The summary line reads back what the agent will read, for example "Reads 2 sources, minus 1 tag."

Two Quick presets include whole visibility tiers in one click: Everything marked public and Signed-in customers only. They pair with the rules below them.

The sensitivity ceiling always caps reach

The Sensitivity ceiling is set on the Boundaries step, not in the rules: Standard, Confidential, or Highly sensitive. Anything above the ceiling is never read, even if a rule includes it. The rules panel shows a count of items that sit above the ceiling and "won't be read", and asks you to confirm before including more than 200 items at once.

Who can use the agent

Also on Boundaries, Who can use it decides which teammates may pick the agent in chat: Everyone, Specific people (teams, roles or people, each allowed or excluded), or Just me. With Specific people, admins and owners never need a grant. With Just me, only you can chat with it. A restricted agent is also left out of Email and Slack answering and cannot hold a council seat on Slack.

Audiences on customer channels

Internal chat uses the asker's own permissions. Customer channels do not have a signed-in teammate behind them, so each one has an audience setting.

Website widget

In the widget editor, under Install → Advanced — access, identity & privacy, the setting Who can this widget answer for has four levels, weakest to strongest:

  • Public knowledge only (the default): only knowledge marked for everyone.

  • Origin lock only: trusts pages on your allowed domains. Easiest, but a technical visitor could bypass it, so use it for low-stakes internal knowledge.

  • Verified embedding: your site proves it holds your signing key on every page load.

  • Signed-in visitors: your site vouches for each logged-in visitor by name. This is the only mode that can tailor answers to who is asking, and it can unlock Gated knowledge based on visitor traits such as plan or customer tier.

Restricted, private and confidential visibility knowledge, and the sensitivity ceiling, are never affected by any of these levels. Set-up details are in Website chat widget.

On a gated Help Center, a visitor who is signed in to the portal is recognized by the chat widget bound to it, so they don't start over as an anonymous visitor. This works only when the widget is set to Public knowledge only and has a signing key. That sign-in only identifies them. It never unlocks internal or Gated knowledge, even if the widget's level is raised later. See Gated access and customer portal.

Email inboxes

An inbox's Knowledge audience is either Public knowledge only or Include internal knowledge. With internal knowledge on, replies from that inbox may quote internal-visibility material, and the editor shows a warning: email has no visitor verification step, so everyone who writes to the inbox gets that wider scope.

Skills on customer channels

Each skill attached to an agent has its own Available to setting (Team & customers, Team only, Customers only) and, for customers, Customers must be Anyone, Verified by email, or Signed in. Some skills are always team only and never run on customer channels.

What a customer-facing agent cannot see

Regardless of scope:

  • Knowledge above the agent's sensitivity ceiling.

  • Knowledge whose visibility excludes the channel's audience.

  • Personal data in answers when PII in answers is set to Redact. The public widget always masks personal data.

  • Anything a Boundaries answer rule blocks, such as blocked topics or competitor recommendations.

If the scope is empty, or every rule is an exclude, the Review step flags it: "nothing is in scope, so this agent reads no sources."

Was this article helpful?
Related articles
Confidence, citations and evidenceAgents & answeringCouncil answersAgents & answeringSkillsAgents & answeringAPI changelogDevelopers